diff options
author | Alberto Sartori <alberto.sartori@huawei.com> | 2023-11-15 16:07:10 +0100 |
---|---|---|
committer | Alberto Sartori <alberto.sartori@huawei.com> | 2023-11-15 16:43:33 +0100 |
commit | e3e3cba99c06d1ee56200800fce727f8c5dd4d41 (patch) | |
tree | 5f610a42bf5feadc67f3986145b0f4430a860c92 /src/utils | |
parent | 145ad96b08aba0aa8c59dd8db44690fb8b6dd9fa (diff) | |
download | justbuild-e3e3cba99c06d1ee56200800fce727f8c5dd4d41.tar.gz |
utils/cpp: add IsAHash function
This function is mainly used to check that the hash of a Digest
received over the wire is a real hash, to prevent a malicious attack.
Diffstat (limited to 'src/utils')
-rw-r--r-- | src/utils/cpp/TARGETS | 7 | ||||
-rw-r--r-- | src/utils/cpp/verify_hash.hpp | 35 |
2 files changed, 42 insertions, 0 deletions
diff --git a/src/utils/cpp/TARGETS b/src/utils/cpp/TARGETS index 7c05472f..578996b2 100644 --- a/src/utils/cpp/TARGETS +++ b/src/utils/cpp/TARGETS @@ -88,4 +88,11 @@ , "hdrs": ["path_hash.hpp"] , "stage": ["src", "utils", "cpp"] } +, "verify_hash": + { "type": ["@", "rules", "CC", "library"] + , "name": ["verify_hash"] + , "hdrs": ["verify_hash.hpp"] + , "deps": [["@", "fmt", "", "fmt"]] + , "stage": ["src", "utils", "cpp"] + } } diff --git a/src/utils/cpp/verify_hash.hpp b/src/utils/cpp/verify_hash.hpp new file mode 100644 index 00000000..ab2a4b45 --- /dev/null +++ b/src/utils/cpp/verify_hash.hpp @@ -0,0 +1,35 @@ +// Copyright 2023 Huawei Cloud Computing Technology Co., Ltd. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +#ifndef INCLUDED_SRC_UTILS_CPP_VERIFY_HASH_HPP +#define INCLUDED_SRC_UTILS_CPP_VERIFY_HASH_HPP +#include <algorithm> +#include <cctype> +#include <optional> +#include <string> + +#include <fmt/core.h> +/// \brief Check if the passed string \p s is a hash. +/// This function is mainly used to check that the hash of a Digest received +/// over the wire is a real hash, to prevent a malicious attack. +[[nodiscard]] static inline auto IsAHash(std::string const& s) noexcept + -> std::optional<std::string> { + if (!std::all_of(s.begin(), s.end(), [](unsigned char c) { + return std::isxdigit(c); + })) { + return fmt::format("Invalid hash {}", s); + } + return std::nullopt; +} +#endif |